CVE-2008-4332 EXPLOIT
7.5
HIGH · CVSS 2.0 · EPSS 2% (pctl 80)
Patch early
A public exploit exists.
Description
SQL injection vulnerability in the showjavatopic function in func.php in PHP infoBoard V.7 Plus allows remote attackers to execute arbitrary SQL commands via the idcat parameter to showtopic.php.
Scoring
| CVSS | 7.5 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
| EPSS | 1.99% — more likely to be exploited than 80% of all CVEs |
| Weakness | CWE-89 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2008-09-30 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| cannot | php infoboard |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | PHP infoboard 7 plus - Multiple Vulnerabilities | 2008-09-25 |
References
- http://secunia.com/advisories/31977
- http://www.securityfocus.com/bid/31405
- https://exchange.xforce.ibmcloud.com/vulnerabilities/45440
- https://www.exploit-db.com/exploits/6566
- http://secunia.com/advisories/31977
- http://www.securityfocus.com/bid/31405
- https://exchange.xforce.ibmcloud.com/vulnerabilities/45440
- https://www.exploit-db.com/exploits/6566
→ the Explorer · watch your stack · NVD